- Log Stream Overview
- Parser Manager
- Parsers Overview
- View Parser Details
- Create a Custom Parser
- Import Sample Logs
- Define a Subset of the Sample Logs
- Add Conditions
- Add Basic Parser Information
- Extract Event Fields
- Extract Mapped JSON Fields
- Select JSON Fields from a List of Key/Value Pairs
- Select Tokenized JSON Fields from the Values in the Sample Log
- Manually Enter JSON Path Expressions
- Reorder Mapped JSON Fields
- Review the Matching JSON Fields and Values
- Add Logic to JSON Field Extraction
- Expressions for Parser Field Extractions and Enrichment Mapping
- Array Log Sample
- Extract Fields Using Regular Expressions
- Reserved Fields
- Extract Mapped JSON Fields
- Add Event Builder Rules
- Review and Save Parser
- Manage Existing Custom Parsers
- Tokenize Non-Standard Log Files
- Customize a Default Parser
- Duplicate a Parser
- Enable or Disable Parsers
- Parser Updates
- Live Tail
- Enrichments
- Event Filtering
Reserved Fields
The chart below lists the a set of reserved fields that cannot be used for mapping fields when configuring conditions in Log Stream. There are two situations in Log Stream where these fields are restricted from use:
Parser Field Extraction – During parser creation in Log Stream, when defining how a parser should extract value from a raw log, you can decide which fields to extract value from and how to map them to Exabeam fields. The set of reserved fields listed below may not be used for building mapping extracted field values.
Enrichment Rules – When building custom enrichment rules on the Enrichments tab in Log Stream, you can build conditions that will map field data from raw logs to Exabeam common information model (CIM) fields. The set of reserved fields listed below may not be used for configuring this field mapping.
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
In addition to the list above, fields that begin with the following prefixes also cannot be used:
exa_m_(Exception – The following metadata fields can be used for mapping fields when building enrichment rules but not when defining parser field extractions:m_tags,m_site_id,m_site_name